Skip to content
Paybob

Installation

Installer options

Every option the installer accepts: database, proxy, ports, versions and unattended installs.

Every question the installer asks can be answered with an option instead, and a few options change how Paybob is set up. Pass options after bash -s --:

Terminal
curl -fsSL https://get.paybob.io/install.sh | sudo bash -s -- --url https://pay.example.com --db local

To see the list on your server, run the installer with --help.

Address

OptionWhat it does
--url URLPaybob's address, for example https://pay.example.com: a host name only, with no path or port. Must be https:// in production. Asked for when not given.
--allow-httpAllows an http:// address. For testing only: passkeys and most payment gateways don't work over plain HTTP. The installation is marked as not for production, and every upgrade repeats the warning.

Database

The default is the bundled MariaDB, which runs next to Paybob and is never reachable from outside the server.

OptionWhat it does
--db localUse the bundled MariaDB (default).
--db remoteUse your own MariaDB 10.6+ or MySQL 8.0+ server.
--db-host HOSTThe database server's host name or IP address.
--db-port PORTIts port (default 3306).
--db-name NAMEThe database name (default paybob).
--db-user USERThe database user (default paybob).
--db-password-file FILEA file whose first line is the database password. Passing the password in a file keeps it out of your shell history.

A database on the same server

Paybob runs inside Docker, so localhost or 127.0.0.1 would mean the container itself, not your server. For a MySQL or MariaDB server running on the same machine, use host.docker.internal as the host (the installer offers to switch to it if you enter localhost). The database server must also:

  • listen on Docker's network, with bind-address = 0.0.0.0 or 172.17.0.1 in its configuration;
  • allow your Paybob database user to connect from 172.28.0.0/16, Paybob's Docker network.

For example, with a password file:

Terminal
echo 'your-database-password' > /root/db-pass && chmod 600 /root/db-pass
curl -fsSL https://get.paybob.io/install.sh | sudo bash -s -- \
  --url https://pay.example.com \
  --db remote --db-host db.example.com --db-name paybob --db-user paybob \
  --db-password-file /root/db-pass
rm /root/db-pass

Use your own proxy

By default Paybob runs its own proxy (Caddy) on ports 80 and 443, which handles HTTPS certificates for you. If the server already runs a web server, or you want to manage HTTPS yourself, turn it off:

OptionWhat it does
--no-proxyDon't run the built-in proxy. Paybob listens on 127.0.0.1:8080 for your own proxy.
--app-port PORTListen on this port instead of 8080.
--public-app-portListen on all network interfaces instead of only 127.0.0.1.

Point your proxy at Paybob's port, and make it forward the original Host header and X-Forwarded-Proto. For example, with nginx:

nginx
location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_set_header Host $host;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}

Ports published by Docker bypass the firewall

With --public-app-port, Paybob's port is reachable from the internet even if ufw or firewalld blocks it, because Docker writes its own firewall rules. Only use it when something outside the server, such as a load balancer, must connect directly. If Cloudflare connects to that port directly, add Cloudflare's IP ranges to TRUSTED_PROXIES in /opt/paybob/app.env so Paybob sees your visitors' real IP addresses.

Host

OptionWhat it does
--install-dockerInstall Docker without asking if it's missing.
--force-unsupported-osContinue on a Linux distribution that isn't officially supported. Docker must already be installed and working.
--yesAccept every prompt: install missing tools, create swap, install Docker.

Version

OptionWhat it does
--version VERSIONInstall this version instead of the latest, for example --version 3.0.1.

Unattended installs

Normally the first admin account and Brand are created in the browser with a one-time link. To create them during installation instead, for example from a provisioning script, pass all of these:

OptionWhat it does
--admin-name NAMEThe admin's name.
--admin-email EMAILThe admin's email address, used to sign in.
--admin-password-file FILEA file whose first line is the admin's password (at least 8 characters).
--brand NAMEThe first Brand's name.
--currency CODEThe Brand's currency, for example USD.
--timezone ZONEThe Brand's timezone, for example Europe/London.

A complete unattended install:

Terminal
echo 'a-strong-admin-password' > /root/admin-pass && chmod 600 /root/admin-pass
curl -fsSL https://get.paybob.io/install.sh | sudo bash -s -- \
  --url https://pay.example.com --db local --yes \
  --admin-name "Jane Doe" --admin-email [email protected] \
  --admin-password-file /root/admin-pass \
  --brand "Example Store" --currency USD --timezone Europe/London
rm /root/admin-pass

After a failed run

OptionWhat it does
--resumeContinue the previous, unfinished installation with its saved settings and secrets.
--cleanupRemove what the unfinished installation created, so you can start over.

See If the installation stops.

Advanced settings

These environment variables change the installer's limits. Use them only if you know why you need them.

VariableDefaultMeaning
PAYBOB_MIN_FREE_MB5120Free disk space required for the installation, in MB.
PAYBOB_MIN_DOCKER_FREE_MB3072Free disk space required for Docker, in MB.
PAYBOB_DIR/opt/paybobWhere the installation lives.

Set them for the installer like this:

Terminal
curl -fsSL https://get.paybob.io/install.sh | sudo PAYBOB_DIR=/srv/paybob bash